Practitioner training scenario
Secure the Meridian Health Portal, step by step.
A fictional patient portal used for hands-on assessment practice. Students work the full assessment lifecycle against a single realistic system, producing the same deliverables a real assessment team would.
- System owner
- David Eggerton
- Meridian Regional Health System, IT Services Division
- Authorizing official
- Dana Okafor
- State Health Agency, Chief Information Officer
- Users
- 180,000 patients, 2,400 clinical staff, 60 administrators
- Hosting
- Commercial cloud IaaS, single region, two availability zones
Seven Sequential Modules
Step 0
Prepare
Confirm stakeholders, draw the authorization boundary, designate the common control provider, and state the risk tolerance for Meridian Health Portal.
Deliverable: Preparation and Stakeholder Package
Step 1
Categorize the System
Set confidentiality, integrity, and availability impact levels for each information type, then complete the Privacy Threshold Analysis.
Deliverable: FIPS 199 Categorization and Privacy Threshold Analysis
Step 2
Select Controls
Choose the baseline that matches your categorization, then designate every control as system-specific, inherited, hybrid, or not applicable.
Deliverable: Control Baseline Selection and Designation Table
Step 3
Implement Controls
Write an implementation narrative for each selected control and assign an owner and target date for the work.
Deliverable: Implementation Narratives
Step 4
Assess Controls
Test the implemented controls, record findings with severity, and upload the evidence that supports each result.
Deliverable: Security Assessment Findings and Evidence
Step 5
Authorize the System
Weigh residual risk and issue a signed authorization decision for Meridian Health Portal.
Deliverable: Authorization Decision Memo
Step 6
Monitor
Set the ongoing reassessment cadence for each control family, work the open POA&M items, and report the current security posture.
Deliverable: Continuous Monitoring Report